andygrove opened a new pull request, #6409:
URL: https://github.com/apache/datafusion-comet/pull/6409

   ## Which issue does this PR close?
   
   Closes #6408.
   
   ## Rationale for this change
   
   Every label run has failed at startup since #4950 gave the `docs` job in 
`ci.yml` `contents: write`, while `ci_label.yml` grants the call only 
`contents: read`. GitHub checks every job in a called workflow against the 
caller's grant when the run starts, including jobs the event skips. As a 
result, no `run-*` label has run anything since #4950 merged.
   
   ## What changes are included in this PR?
   
   - `ci_label.yml` now grants `contents: write`, the union of what `ci.yml`'s 
jobs request, and its comment now lists the `docs` job. No job that runs on a 
label event gets more access:
     - `ci.yml`'s default is `contents: read`, and only `docs` asks for write.
     - `docs` runs only on `main`.
     - A pull request from a fork gets a read-only token regardless.
   - `dev/ci/check-ci-config.py` compares every `permissions:` block in 
`ci.yml` against the grant in `ci_label.yml`. The next job that asks for more 
fails preflight instead of silently disabling the labels.
   
   ## How are these changes tested?
   
   - `python3 dev/ci/check-ci-config.py` passes.
   - With the grant reverted to `contents: read`, the script fails with "ci.yml 
requests `contents: write`, but ci_label.yml grants the call at most `contents: 
read`, so every label run fails at startup".
   - `actionlint -color --shellcheck=off` passes.
   - A label run on this pull request uses this branch's `ci_label.yml`, so 
adding a `run-*` label here exercises the fix directly.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to